🔴 Breaking
Thursday, September 24, 2026
Solo Ops

Half of UK businesses hit by cyber breaches

· · 5 min read
Half of UK businesses hit by cyber breaches - uk cyber breaches
Aqua Security’s platform demonstrates deeper runtime control by monitoring activity inside containers, virtual machines, Kubernetes clusters, and serverless workloads.

UK government data shows nearly half of all businesses experienced a cyber breach or attack in the past year. This affected about 612,000 firms, with medium-sized companies hit 65% of the time and large enterprises at 69%. The risk increases as organizations expand, adding employees, suppliers, and cloud services that outstrip initial security measures.

Most businesses start with basic security steps, including vulnerability scans for exposed systems, outdated software, unsafe configurations, and excessive permissions. These measures identify potential entry points but rarely detect ongoing intrusions. They highlight where an attacker might gain access rather than revealing whether someone is already inside the system.

Wiz, a cloud security company, built its reputation on mapping assets, vulnerabilities, and pathways to sensitive data. Its Wiz Sensor extends this visibility into active workloads, tracking live activity while linking it to identities, exposures, and data context. This provides immediate details about suspicious connections, something static vulnerability lists cannot offer.

The core issue remains that stolen credentials can cause damage before the next scheduled scan. Questions about detecting unusual file access, unexpected connections, or movement between systems reveal the difference between theoretical security and practical defense. Some vendors label this “continuous monitoring,” but the term often describes scheduled checks for misconfigurations rather than real-time visibility into processes, connections, or user behavior.

Stolen credentials fuel most breaches

Stolen credentials represent the most common attack vector. An intruder using a legitimate employee or contractor account may initially appear normal. Critical follow-up questions include why an account is accessing a production database at 2 a.m., why it’s retrieving files it has never touched before, and whether the session can be terminated before regular business hours resume.

Aqua Security’s platform demonstrates deeper runtime control by monitoring activity inside containers, virtual machines, Kubernetes clusters, and serverless workloads. It can prevent unauthorized executables from running in containers, but even this capability does not resolve whether to notify insurers, take a service offline, or delay client notifications.

The UK’s Cyber Security Breaches Survey highlights the urgency of real-time monitoring. Twenty-nine percent of businesses reported attacks occurring at least weekly. A tool that only updates its list of missing patches differs significantly from one that watches live processes. An intruder can traverse systems in minutes and remain hidden for weeks, rendering scheduled scans ineffective if the breach begins that night.

Wiz Sensor observes workload execution, file changes, and live connections. When combined with Wiz Defend, it incorporates cloud and SaaS logs while adding broader context from its Security Graph. The difference is clear: an unusual connection carries more weight when it originates from an exposed container with known vulnerabilities, heading toward sensitive storage.

Not all monitoring equals real protection

Not all vendors provide the same level of detail. Some focus on discovery, while others prioritize blocking. Key questions include what “continuous” monitoring actually covers, whether it tracks processes, file changes, and live network activity, which events trigger automatic blocking, and which workloads lack runtime coverage.

Orca Security’s SideScanning tool can discover workloads across cloud accounts without requiring agent installation. The company later added an eBPF-based sensor for process-level monitoring across Linux, Windows, and Kubernetes environments. However, the effectiveness depends on sensor placement. Forgotten test environments, lingering contractor access, or abandoned cloud accounts may appear in discovery scans but lack active protection, leaving them vulnerable to exploitation.

Business growth exposes additional vulnerabilities. Security plans designed for a small team may fail to account for new cloud accounts, test environments, contractors, or AI tools introduced later. These additions often evade static scans because they were not part of the original risk assessment. The problem frequently stems not from a single error but from overlooked test environments, unrevoked contractor access, or unused cloud accounts.

Speed decides breach impact or containment

The distinction between detecting a breach and stopping one lies in response speed. Wiz Sensor integrates runtime monitoring with its Security Graph, offering context for every suspicious event. If an attacker uses a stolen credential to access a database at an unusual hour, the platform does more than flag the activity—it reveals whether the database is exposed, which user account was compromised, and what data is at risk. This level of detail helps security teams decide whether to revoke the session immediately, escalate the alert, or isolate the affected system. Without real-time linkage, an intruder could move undetected between workloads, exfiltrate data, or install malware before the next scheduled scan.

The challenges intensify as businesses scale. Security setups designed for small teams may overlook new cloud accounts, supplier integrations, or AI-driven tools introduced afterward. These additions often slip through because they were not part of the initial risk assessment. The UK’s Cyber Security Breaches Survey found that 29% of attacked businesses faced incidents at least weekly, yet many still rely on scheduled vulnerability scans instead of live monitoring. The difference becomes clear when comparing a tool that refreshes its patch list daily with one that tracks active processes, file changes, and network behavior in real time.

Leave a Comment